1. samuk1000

    samuk1000 Private E-2

    Since AVG went premium, I haven't used a antivirus on my laptop.Things got slower and slower and last night the system broke down.All of my internet connections have been lost on my laptop and i am now getting errors.I cannot run hijack this, I cannot start using "run" services, msconfig etc without thm closing within seconds. Services are not loading. I cannot run windows installer. I am getting error when trying to connect to internet and all my connections have disappeared from the folder.I ran spybot and it found a whole host of spyware, most notably SMITFRAUD which it has been unable to remove. I have successfully booted in safemode and fixed a massive list of 01 entries not to allow connections to any of the antivirus sites or spyware sites, eg hijack this, norton, mcafree, kapersky online etc. I still have command spyware which has not been able to be fixed.Ad-aware keeps finding 1 registry key (windows)My "start" bar at the bottom of the screen has changed theme to a dull grey from the green windows XP theme.Basically I'm concerned Ive lost the use of the laptop.I will go through Hijack this tutorial as I feel confident to do that.Here is a Hijack this scan from safemode....it was very hard to boot in safemode as F8 does not work and running msconfig only worked for 1 or 2 seconds, so I had to change the bootini in that time and hit return to confirm...Hope you can help, this seems like the worst problem ever...As stated I cannot get online with the laptop,this is another computer:
     
    Last edited by a moderator: Jun 15, 2007
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!
    AVG is still freeware ....running your system without anti-virus software is a serious no-no.
    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. samuk1000

    samuk1000 Private E-2

    I have gone through as much of the above process as possible.

    At the moment I have no way to access the internet on the laptop, because all of the connections have been deleted by the malware presumably. Other problems include that installer cannot be run.

    However, I performed Spybot scan in normal and safe mode. I keep getting COMMAND spyware and it cannot be deleted even on reboot in safemode.

    I could not run a CounterSpy check because the installer would not work, even in safe mode, so I installed AVGantispy.

    It picked up:

    Adware.Roguesuspect and several others (4 totally)
    (logfile to be attached as .txt)

    I could not run any online scans as my wireless connection and all other connections that had been set up previously do not appear. When I click in internet options/connections/add I get the error:

    "Cannot load the remote acess connection manager service.
    Error 711: A configuration error on this computer is preventing this connection.,click more info or search help and support center for this error number."

    There is no more info button.

    The only reason I have been able to run the steps is by downloading installers from another PC and transferring USB to laptop.

    On reboot in normal mode, same problem, so I will also attach a hijack this log to this post. Thanks for the offer of support.

    Total attachments:

    AVGAntispyware log
    Hijack this log
    runkeys
    newfiles
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You haven't attached anything ...are you having problems doing so?
     
  5. samuk1000

    samuk1000 Private E-2

    hijackthis (from safemode only possible --- sorry)
    runkeys
    shownew
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. samuk1000

    samuk1000 Private E-2

    Hi Tim,

    It is just saying attachment in progress under attachment errors, not giving the confirmation,

    Sam
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try attaching only one log at a time and after it is attached. Edit the message and attach a second and then a third. Note the fourth log has to be in a second message.
     
  9. samuk1000

    samuk1000 Private E-2

    Chaslang, thanks, will do that now.

    Will take an extra 10 minutes to get AVGlog as I'm having to reboot computer every five minutes because it is heavily attacked,

    Sam
     

    Attached Files:

  10. samuk1000

    samuk1000 Private E-2

    Inline logs deleted!


    could not attach

    Hi,

    sorry Chalang, I will do that presently...

    Sam
     
  11. samuk1000

    samuk1000 Private E-2

    Inline logs deleted!

    could not attach
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Inline logs are too hard to read!!! They will be deleted since we cannot spend the time it takes to read them due to the formatting getting corrupted. Please put the logs you could not attach into a ZIP file and attach the ZIP file.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG Antispyware should have been run before not after GetRunKey, ShowNew or HJT.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the below procedure:

    ChodeFix - How download and run

    After running that, you must install and rename HijackThis exactly as request in step 7 of the READ ME!!

    Then attach (if possible otherwise ZIP) new logs from GetRunKey and HJT.
     
  15. samuk1000

    samuk1000 Private E-2

    Hi Chaslang,

    I did do the scan before, but as stated, I have to transfer it (AVG log) from the broken computer (laptop) to this computer in order to upload because the malware has broken my laptop from connecting to internet...

    Chodefix was run. It could not find any of the specified files. Other than that, it seems to have run its process.

    Zip file attached and includes AVG log (coming shortly)

    PLEASE NOTE THE ATTACHED ZIP FILE IS NOT THE LATEST AFTER NEW HIJACK THIS INSTALL AND RENAME + NEW RUNLOGS ETC.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Did you see message number 14? That is one of your main problems. You have a Chode infection and need to run that procedure and then try attach the new logs. I will more than likely have to make a special version of ChodeFix afterwards tailored for just you to complete the fixes.
     
  17. samuk1000

    samuk1000 Private E-2

    Done:

    Latest - includes AVGScan, newfiles, runlogs, hijack this in zip.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 8
    My Global Search Bar

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment



    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: SpoofBHO Class - {F67EEB12-AB09-11DB-A6F1-260856D89593} - C:\WINDOWS\se_spoof.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O21 - SSODL: Vbamidat - {E456A969-8F2D-4F8F-8194-BA5B8549F827} - C:\WINDOWS\system32\bmpegdde.dll

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs (you should not need to ZIP them anymore) and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  19. samuk1000

    samuk1000 Private E-2

    Still cannot create an internet connection
    Not recognising built in microphone on computer.

    Cannot install java in norml mode,also could not uninstall last version -

    "Installer service could not be accessed, This can occur if you are running windows in safe mode, or if the windows installer is not correctly instralled."

    This occurs during boot in normal mode.

    ERROR window onn install attempt

    Installer: Wrapper.CreateFile failed with error 32. The process cannot access the file because it is in use by another process.

    Hijack this run and fixed suggested files (log on its way)
    Avenger setup and run (log on its way)
    CC Cleaner run attempted:

    CCListBar Run Time Error '0' then "needs to close"
    The instruction at "0x773f62fb' referenced memory at "ditto" The memory could not be "read"Click ok to terminate

    Get Run Keys (log on the way)
    Show New Files (log on the way)
     
  20. samuk1000

    samuk1000 Private E-2

    attachments...should I try the ccleaner in safemode?
     

    Attached Files:

  21. samuk1000

    samuk1000 Private E-2

    Hijack This log looks clean now...but still same problems as above.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the HijackThis log as requested and let us decide whether it is clean or not.

    In the future, please remember to finish running GetRunKey by closing the popup notepad windows, before running ShowNew. This is mentioned in the READ & RUN ME.

    Delete the below file:
    C:\crtlsf.dll

    At this point I'm expecting that any remaining issues your having are not due to malware and I may be sending you off to the Software Forum. However please run the below first and let me know if if helps to repair your internet connection:

    XP TCP/IP Repair
     
  23. samuk1000

    samuk1000 Private E-2

    Thanks for the help so far. Still getting the configuration of RAS error 711 when trying to add a new connection.

    HJT log attached.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log is not clean and it even looks like you did not do what was requested in message # 18. Let's try again but the total procedure is slightly different since all files were deleted last time by Avenger.

    Make sure when you run the below procedure that only one user account is logged in (i.e. do not use Switch User before or during) also make sure that no unnecessary process are running and when I request that browsers are closed you must make sure that you do close the browsers.

    First goto Add/Remove programs and uninstall TrustIn Contextual


    Run HijackThis and select Do a system scan only. Then select the following lines but DO NOT CLICK FIX Checked until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: SpoofBHO Class - {F67EEB12-AB09-11DB-A6F1-260856D89593} - C:\WINDOWS\se_spoof.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O21 - SSODL: Vbamidat - {E456A969-8F2D-4F8F-8194-BA5B8549F827} - C:\WINDOWS\system32\bmpegdde.dll

    After clicking Fix Checked, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now! If you still get an error when trying to connect to the internet, youmust give exact word for word error messages. You never mentioned RAS 711 until your last message. This is more than likely not a malware issue but rather an issue within your OS. Are you using a dialup connection?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds